Defence and armed forces – guidance

Defence Assurance and Information Security: defence industry/list X

Details of the responsibilities and processes of the Defence Assurance and Information Security (DAIS).

DAIS defence industry ICT accreditation

DAIS service

A role of DAIS is to provide a range of support to defence and its industry partners to achieve accreditation, including:

  • oversight, tracking and provision of management information for all defence accreditation activity
  • advice and guidance on the subject of accreditation
  • assessment of evidence and Risk Management Accreditation Document Sets (RMADS)
  • final sign-off and provision of a certificate of accreditation

Accreditation

Accreditation confirms that information and communication technology (ICT) systems embody appropriate security to allow MOD information to be stored and processed with an acceptable level of risk.

The Defence Assurance Risk Tool (DART) must be used to register all ICT systems owned or used by MOD industry partners, where those ICT systems are either connected to HMG networks or store or process OFFICIAL-SENSITIVE information or more highly classified information. These ICT systems must be accredited before use and subsequently have their security managed thereafter.

The authorities responsible for the systems requiring accreditation must ensure that this accreditation is obtained before storing or processing MOD information.

DAIS is the sponsor of the accreditation process for MOD, providing support and advice and overseeing accreditation activity across defence. The system, or a subset of a system, requiring accreditation is known as a target of assurance (TOA).

All requests to accredit ICT are processed through the Defence Assurance Risk Tool (DART), which enables the tracking of TOAs and the provision of management information.

The DART methodology includes a triage process that takes account of risk and assigns one of the following assessment paths:

  • DAIS assessment
  • MOD Top Level Budget Holder accreditor assessment
  • self assessment and provision of evidence to DAIS

Accreditation requires the provision of evidence and approval through the Defence Assurance and Information Security (DAIS) team or delegated authority processes and a DART produced certificate to be provided.

Start accrediting your ICT system

  1. register the system/application that requires accreditation (opens DART for those with RLI access)
  2. if you have not used DART before, you will need to ‘Register’ first; if you have, just ‘Login’
  3. follow the instructions within the tool; If you get stuck, open the user guide by clicking ‘Help’

If you do not have access to the RLI, you will not be able to access DART directly. In this circumstance:

  1. save a copy of the relevant DAIS accreditation request form and annexes to a suitable location
  2. remember that information categorised as OFFICIAL-SENSITIVE or above must not be transmitted in clear over the Internet
  3. post the completed accreditation request forms to:

Service Delivery Team,
DAIS, Room X007,
Bazalgette Pavilion,
RAF Wyton,
Huntingdon,
Cambs,
PE28 2EA.

Get advice and guidance on accreditation in general

Call our customer support line on 01480 446311 or 95371 4564 or email CIO-DSAS-ContactPoint@mod.uk.

Find out who the accreditor is for your system

  1. login to DART and view your system and the assigned accreditor will be visible
  2. if you do not have a DART account but need to know, call our Customer support line on 01480 446311 or 95371 4564 or e-mail CIO-DSAS-ContactPoint@mod.uk

Joint Security Co-ordination Centre (JSyCC)

The JSyCC enables ‘defence information assurance’ assessment through the conduct and coordination of MOD information security incident management and related risk analysis activity.

Additionally, it is a focal point for ‘information security alerts’ and associated ‘warning and response’ activities.

JSyCC responsibilities:

We are responsible for

  • operational co-ordination and management of the immediate response, warning and reporting, including the investigative oversight and follow-up actions, for all reported Defence information assurance/information security incidents involving the loss, compromise or leakage of protectively marked official information and/or equipment
  • operational information security risk management, trend analysis and related policy. This includes the management of the MOD Information Security Incident Reporting Scheme (MISIRS) and supporting database, together with the drafting of responses to Parliamentary Questions, Freedom of Information (FOI) requests etc
  • the provision of the Defence industry warning and reporting point (WARP) responsible for the coordination of the response and management of all Defence industry information security incidents, including List X
  • the coordination of all law enforcement and counter intelligence for information security incidents

Contact details

If you want to know more about JSyCC, use the contact details below:

JSyCC
X017, Bazelgette Pavilion
RAF Wyton
Huntingdon
Cambs, PE28 2EA

Point of Contact: JSyCC Ops 0306 770 2187

JSyCC Duty Officer (out of hours) 07768 558 863

Email: CIO-DSAS-JSyCCOperations@mod.uk